CVE-2026-16443 HIGH

CVE-2026-16443: Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation

Vendor Red Hat
Product Red Hat Build of Keycloak
Weakness CWE-347
Published August 5, 2026
Last update August 5, 2026

CVSS base score

7.4/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.

Key dates

02Disclosure timeline

August 5, 2026 CVE published

Related vulnerabilities

04Related CVE